Google Paid $1,000 for a Bug Worth Six Figures
Thursday's Chrome patch fixed the sixth actively exploited zero-day of 2026. The researcher who found it got $1,000. The gap between those numbers is the entire gray market.
The World Times
Thursday's Chrome patch fixed the sixth actively exploited zero-day of 2026. The researcher who found it got $1,000. The gap between those numbers is the entire gray market.
The arrayref attack wasn't a supply chain failure — it was the Rust ecosystem's build-time code execution model working exactly as designed.
The Chrome security team's record-breaking bug haul isn't a cleanup story—it's a demonstration of an asymmetric capability that won't stay pointed inward for long.
The Krebs report on malware-laden Android TV boxes misses the real scandal: a multi-hundred-million-dollar gray market for residential IPs, fueled by ad-tech firms, price scrapers, and SEO consultants who'd rather not ask where the addresses come from.
Microsoft had 144 days to fix a self-propagating AI worm in Word. The real problem isn't the patch timeline — it's that the product category itself has no coherent security model.
Codex Security's real innovation isn't AI — it's sandbox validation that proves a vulnerability is real before reporting it. The security industry could have built this years ago. It chose not to.
A hacker wiped Romania's land registry and its backups on July 14. An offline copy nobody talks about is the only reason the country still knows who owns what. The cybersecurity industry should be embarrassed.
The outrage over a Mullvad co-founder's donation to a Swedish far-right party reveals an uncomfortable truth the privacy movement has dodged for years: universal privacy means protecting people you despise.
A GitHub account called Exploitarium is dumping unpatched zero-days with a note to report them yourself. The real story isn't one more irresponsible hacker — it's the industry that made reporting bugs feel like a sucker's game.
CVE-2026-32610 is the latest reminder that the CORS spec wasn't designed for the world it now governs — and blaming developers won't fix it.
The Red Hat npm compromise isn't a story about supply chain fragility. It's a story about what happens when security researchers publish functional worm code and call it transparency.
Cloudflare's Saturday Turnstile update sent the privacy community into orbit. The real story is what their indignation reveals about who actually benefits from frictionless bot detection — and who doesn't.